An issue was discovered in Concrete CMS through 8.5.5. Stored XSS can occur in Conversations when the Active Conversation Editor is set to Rich Text.
{
"source": "CPE_RANGE",
"cpe": "cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "8.5.5"
}
]
}